Timing Attack Vulnerability in Misskey Social Media Platform
CVE-2026-47746
8.9HIGH
What is CVE-2026-47746?
Misskey, an open-source federated social media platform, is vulnerable to timing attacks affecting the JSON-LD signature validation and compaction processes. This vulnerability arises because the parsing context for JSON-LD signatures is not consistently shared during verification and subsequent processing. As a result, an attacker could exploit this flaw to have untrusted information accepted as legitimate, leading to potential integrity loss. The issue has been addressed in version 2026.5.4, making it essential for users to upgrade to this version to mitigate the risk.
Affected Version(s)
misskey >= 12.37.0, < 2026.5.4
